When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party ICT service providers, updating contract clauses, and documenting incident escalation workflows. That was the easy part.
Now, in year two, regulators are asking a far harder question: can your SOC actually see the attack?
The shift is from documentation to demonstration. Supervisory authorities are no longer satisfied with policies on paper — they want evidence that detection, classification, escalation, and reporting capabilities function under real conditions. For CISOs and SOC leaders at banks, payment institutions, insurance firms, investment firms, and their critical ICT providers, this is the moment where visibility gaps stop being an internal risk metric and become a regulatory finding.
Why Year Two Is Different
Year one of DORA enforcement was largely about structural compliance: registers of information for third-party providers, contractual provisions, governance frameworks, and resilience strategies. Competent authorities accepted that organizations were building.
Year two is about operational proof. The supervisory focus now lands squarely on the capabilities DORA demands in practice:
- Detection: The ability to identify anomalous activities — including anomalous network behavior and ICT-related incidents — in near real time across the entire estate, including third-party and cloud-hosted systems.
- Classification: Applying DORA's materiality thresholds to determine whether an incident qualifies as "major" based on clients affected, downtime, geographic spread, data losses, and costs.
- Reporting: Meeting the mandatory notification timelines — an initial notification to the competent authority within hours of classifying an incident as major (and no later than 24 hours from awareness), an intermediate report within 72 hours, and a final report within one month.
- Testing: Executing the full resilience testing program, including threat-led penetration testing (TLPT) aligned with the TIBER-EU framework for entities designated in scope.
The uncomfortable truth many organizations are confronting: an incident classification workflow documented in a GRC tool is worthless if the SOC cannot detect the incident in the first place, or cannot answer the classification questions — how many clients affected, what duration, what data impact — because the telemetry doesn't exist.
The Visibility Problem Behind the Compliance Problem
In our IR engagements across financial sector clients, the same visibility gaps surface repeatedly, and they map directly onto DORA's reporting requirements:
1. No asset-aware detection coverage. DORA's materiality thresholds require knowing which systems serve which clients and which critical functions. If your SIEM doesn't correlate alerts against a maintained asset inventory tied to business services, you cannot answer "how many clients affected" within the reporting window. Detection rules deployed without asset context produce alerts, not answers.
2. Third-party and cloud blind spots. DORA explicitly extends accountability to ICT third-party service providers. Many SOCs still have weak or no telemetry from SaaS platforms, managed service providers, and cloud control planes. An attacker — or a plain operational failure — inside a critical provider's environment can trigger a DORA reportable event that the financial entity never sees until the provider notifies them, potentially blowing the regulatory clock.
3. Classification paralysis under pressure. The 24-hour initial notification window is unforgiving. Organizations that haven't pre-built incident classification decision trees — mapped to DORA's thresholds and rehearsed under realistic conditions — burn the first 12 hours in internal debate about whether the incident is "major." That debate must happen in minutes, driven by pre-agreed criteria and data the SOC already collects.
4. Testing theater instead of resilience testing. DORA requires a risk-based digital operational resilience testing program, with advanced TLPT every three years for in-scope entities. Some organizations treated year-one testing as checkbox vulnerability scans. Year two scrutiny will distinguish between a scan report and intelligence-led red teaming that actually exercises detection and response — the kind of testing that reveals whether the SOC sees the attack at all.
5. Clock-start ambiguity. A recurring failure mode: disagreement about when the entity became "aware" of the incident, which starts the reporting clock. Without documented awareness criteria — first high-fidelity alert triaged, first confirmed IOC, first third-party notification — organizations either report late or report prematurely and inconsistently.
Executive Takeaways
1. Map detection coverage to DORA materiality, not just MITRE ATT&CK. Build a coverage matrix that ties your SIEM detections to the systems supporting critical or important functions. If you cannot produce an answer to "clients affected, downtime, data losses, geographic spread" from your telemetry within two hours of an incident, your detection program is not DORA-ready regardless of how many ATT&CK techniques you cover.
2. Close the third-party telemetry gap contractually and technically. DORA year-two supervision will probe ICT third-party risk management hard. Verify that contracts with critical providers include incident notification SLAs shorter than your own regulatory clock, and establish direct telemetry ingestion (API logs, cloud audit trails, provider security events) rather than relying solely on provider attestations.
3. Rehearse the classification workflow as a live drill, not a tabletop discussion. Run at least two full-lifecycle exercises per year that go from simulated detection through classification, initial notification drafting, intermediate report, and final report — with actual timestamps. Measure whether you can produce a defensible initial notification within four hours of awareness, comfortably inside the 24-hour outer limit.
4. Define and document "awareness" criteria now. Write down precisely what triggers the reporting clock: which alert severities, which confirmation steps, which roles declare awareness. Have legal, compliance, and the SOC sign off. In an examination or post-incident review, this document is your defense against a late-reporting finding.
5. Treat TLPT as a detection validation, not an adversary simulation vanity exercise. If you're designated for threat-led penetration testing, scope it with your blue team in the loop (purple-team style where permitted). The deliverable that matters to a supervisor is evidence that your SOC detected the test scenarios — and a remediation plan for the scenarios it missed.
6. Instrument for the final report, not just the initial one. The one-month final report requires root cause, remediation actions, and lessons learned. SOCs that don't preserve forensic evidence, maintain investigation timelines, and document response actions as they go will struggle to produce a credible final report. Build post-incident documentation into your IR runbooks as mandatory fields, not afterthoughts.
The Bottom Line
DORA year one rewarded organizations that could produce documents. Year two will expose those that cannot produce detection. The regulatory question has shifted from "do you have a plan?" to "show me the alert, the timeline, and the report you filed — and prove it happened inside the window."
For SOC leaders, this is actually an opportunity: DORA gives you regulatory air cover to fund the visibility investments — asset-aware detection engineering, third-party telemetry, rehearsed classification workflows — that mature security programs needed anyway. Use it.
Organizations that treat year two as more paperwork will discover, at the worst possible moment, that their SOC couldn't see the attack — and now there's a regulator asking why.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.